|
|
|
|
| |
Credit:
The information has been provided by Microsoft Product Security.
The original article can be found at: http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx
|
| |
Affected Software:
* SQL Server 7.0 Service Pack 4 (KB948113) - SQL Server 7.0 Service Pack 4 (KB948113) - Elevation of Privilege - Important - None
* SQL Server 2000 Service Pack 4 (KB948110) - SQL Server 2000 Service Pack 4 (KB948111) - Elevation of Privilege - Important - None
* SQL Server 2000 Itanium-based Edition Service Pack 4 (KB948110) - SQL Server 2000 Itanium-based Edition Service Pack 4 (KB948111) - Elevation of Privilege - Important - None
* SQL Server 2005 Service Pack 2 (KB948109) - SQL Server 2005 Service Pack 2 (KB948108) - Elevation of Privilege - Important - None
* SQL Server 2005 x64 Edition Service Pack 2 (KB948109) - SQL Server 2005 x64 Edition Service Pack 2 (KB948108) - Elevation of Privilege - Important - None
* SQL Server 2005 with SP2 for Itanium-based Systems (KB948109) - SQL Server 2005 with SP2 for Itanium-based Systems (KB948108) - Elevation of Privilege - Important - None
* Microsoft Data Engine (MSDE) 1.0 Service Pack 4 (KB948113) - Microsoft Data Engine (MSDE) 1.0 Service Pack 4 (KB948113) - Elevation of Privilege - Important - None
* Microsoft SQL Server 2000 Desktop Engine (MSDE 2000) Service Pack 4 (KB948110) - Microsoft SQL Server 2000 Desktop Engine (MSDE 2000) Service Pack 4 (KB948111) - Elevation of Privilege - Important - None
* Microsoft SQL Server 2005 Express Edition Service Pack 2 (KB948109) - Microsoft SQL Server 2005 Express Edition Service Pack 2 (KB948108) - Elevation of Privilege - Important - None
* Microsoft SQL Server 2005 Express Edition with Advanced Services Service Pack 2 (KB948109) - Microsoft SQL Server 2005 Express Edition with Advanced Services Service Pack 2 (KB948108) - Elevation of Privilege - Important - None
Windows Components:
* Microsoft Windows 2000 Service Pack 4 - Microsoft SQL Server 2000 Desktop Engine (WMSDE) (KB948110) - Elevation of Privilege - Important - None
* Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 - Microsoft SQL Server 2000 Desktop Engine (WMSDE) (KB948110) - Elevation of Privilege - Important - None
* Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 - Windows Internal Database (WYukon) Service Pack 2 (KB948109) - Elevation of Privilege - Important - None
* Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Microsoft SQL Server 2000 Desktop Engine (WMSDE) (KB948110) - Elevation of Privilege - Important - None
* Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 - Windows Internal Database (WYukon) x64 Edition Service Pack 2 (KB948109) - Elevation of Privilege - Important - None
* Windows Server 2008 for 32-bit Systems* - Windows Internal Database (WYukon) Service Pack 2 (KB948109) - Elevation of Privilege - Important - None
* Windows Server 2008 for x64-based Systems* - Windows Internal Database (WYukon) x64 Edition Service Pack 2 (KB948109) - Elevation of Privilege - Important - None
*Windows Server 2008 server core installation affected. For supported editions of Windows Server 2008, this update applies, with the same severity rating, whether or not Windows Server 2008 was installed using the Server Core installation option.
Memory Page Reuse Vulnerability - CVE-2008-0085
An information disclosure vulnerability exists in the way that SQL Server manages memory page reuse. An attacker with database operator access who successfully exploited this vulnerability could access customer data.
CVE Information:
CVE-2008-0085
Convert Buffer Overrun - CVE-2008-0086
A vulnerability exists in the convert function in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system.
CVE Information:
CVE-2008-0086
SQL Server Memory Corruption Vulnerability - CVE-2008-0107
A vulnerability exists in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system.
CVE Information:
CVE-2008-0107
SQL Server Buffer Overrun Vulnerability - CVE-2008-0106
A vulnerability exists in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system.
CVE Information:
CVE-2008-0106
|
|
|
|
|